Privacy policy
What we hold about you, why, and for how long.
This policy is a first draft and has not been reviewed by a lawyer. It describes accurately what the platform does with data. It has not been checked against PIPEDA, GDPR or any other privacy law.
Last changed: 5 September 2026.
What we hold about you
Because you signed up: your name, your email address, and the address of your page.
Because you use it: what you have written, the images you have uploaded, the clients you have added — their names, email addresses and any notes you keep about them — the time you have logged, and the record of what has been bought.
Because a payment happened: a reference to the payment, the amount, and when. Card numbers are handled by Stripe and never reach us.
Because a browser asked for a page: ordinary web server records — the address asked for, the time, the IP address and the browser's own description of itself. These are kept for a short period for security and to work out what is broken.
What we do not do
We do not sell it. We do not share it with anybody to advertise to you. We do not use what you write to train a model.
Who else touches it
- Stripe, to take payments.
- Resend, to send the email we send.
- Laravel Cloud and Cloudflare R2, to run the service and store files.
- Sentry, to tell us when something breaks.
Each of them holds only what is needed to do its part.
When something goes wrong, a report of the moment it broke is sent to Sentry so somebody can fix it. It says which site it happened on and the account number of whoever was signed in — not their name or address — along with the page asked for and the error itself. Passwords, keys, tokens and anything else that reads like a secret are taken out before it is sent.
If you connect your own key to use the assistant — from Anthropic or OpenAI — your writing is sent to whichever one the key belongs to when you ask it something, and not otherwise. That is your account and your agreement with them; we pass the question along and keep nothing. The key itself is stored encrypted and is never shown back to you or to anybody else.
Your clients' data
You put it there, so as far as the law is concerned you decide what happens to it and we process it on your behalf. If one of your clients asks you to remove their record, you can delete it — permanently — from the work panel.
How long we keep it
- While your membership is live: as long as you want it.
- After you cancel: a stated period, which we tell you at the time and remind you of about a week before it ends. Then we let go of it.
- A deleted site sits in a recycling bin for a further period before it is destroyed.
- Backups are kept on a rolling schedule and age out.
What you can ask for
A copy of what we hold, a correction, or deletion. Write to the address on the report page and we will answer within thirty days.
Deleting your account deletes your pages, your client records and your logged time. Records of payments are kept for as long as tax law requires.
Cookies
One, to keep you signed in. There is no analytics and no advertising cookie on Yoursellf's own pages.
Pages our customers write are theirs, and a customer may add their own Google Analytics. That collection is theirs, under their own policy.
Security
Passwords are hashed. Sign-in links are stored hashed and expire. Uploads are checked by their contents rather than their name, and files that can carry script are refused. Backups are encrypted.
If we ever have a breach that puts you at real risk, we will tell you.